Skip to content

Commit

Permalink
Added ordinal of ShellExec_RunDLL
Browse files Browse the repository at this point in the history
  • Loading branch information
Swachchhanda Shrawan Poudel authored and Swachchhanda Shrawan Poudel committed Nov 16, 2024
1 parent 5d1cf4b commit 8acb167
Showing 1 changed file with 3 additions and 1 deletion.
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,9 @@ logsource:
product: windows
detection:
selection_openasrundll:
CommandLine|contains: 'ShellExec_RunDLL'
CommandLine|contains:
- 'ShellExec_RunDLL' # rundll32 SHELL32.DLL,ShellExec_RunDLL "cmd.exe" "/c calc.exe"
- '#572' # rundll32 SHELL32.DLL,ShellExec_RunDLL "cmd.exe" "/c calc.exe"
selection_suspcli:
CommandLine|contains:
# Add more LOLBINs and Susp Paths
Expand Down

0 comments on commit 8acb167

Please sign in to comment.